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Abstract 

This work derives bounds on the jamming capacity of a slotted ALOHA system. A system with n legitimate users, 
each with a Bernoulli arrival process is considered. Packets are temporarily stored at the corresponding user queues, 
and a slotted ALOHA strategy is used for packet transmissions over the shared channel. The scenario considered 
is that of a pair of illegitimate users that jam legitimate transmissions in order to communicate over the slotted 
ALOHA channel. Jamming leads to binary signaling between the illegitimate users, with packet collisions due to 
legitimate users treated as (multiplicative) noise in this channel. Further, the queueing dynamics at the legitimate 
users stochastically couples the jamming strategy used by the illegitimate users and the channel evolution. 

By considering various i.i.d. jamming strategies, achievable jamming rates over the slotted ALOHA channel are 
derived. Further, an upper bound on the jamming capacity over the class of all ergodic jamming policies is derived. 
These bounds are shown to be tight in the limit where the offered system load approaches unity. 
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I. Introduction 

A typical slotted ALOHA system [1], [3], [13] comprises of a collection of legitimate users following a pre- 
arranged strategy to gain access to resources and communicate with each other Our work focuses on using jamming 
as an unconventional communication mechanism to achieve a non-zero throughput in a slotted ALOHA system. 
In this mechanism, an illegitimate jamming transmitter that has gained entry into a slotted ALOHA system jams 
legitimate transmissions, and the resulting "collisions" in the system are then detected by an illegitimate jamming 
receiver Such a jamming -based communication strategy is parasitic in nature and can remain undetected without 
proactive effort by the legitimate entities in the slotted ALOHA system. In this work, we employ an information 
theoretic approach to determine upper and lower bounds on the capacity of this jamming-based communication 
system, under the constraint that jamming does not result in instability of the legitimate user queues. It is intuitively 
clear that the with such a constraint, the capacity of the jamming channel will converge to zero as the offered load 
(due to legitimate users) approaches unity. Our bounds verify this intuition, and we show that both the upper and 
lower bounds converge to zero as the offered load approaches unity. 

A vast body of literature exists that studies the effect of illegitimate communication strategies that exploit inherent 
weaknesses in conventional systems. Covert communication is one such area of research where the goal of the 
illegitimate communication system is to exploit these weaknesses while remaining undetected by the legitimate 
system. A covert channel is loosely defined as an unintended or unauthorized communication path through a 
medium that violates the security policy of that medium. Along the lines of our jamming -based communication 
system, such channels are parasitic in nature, and reduce the capacity of the legitimate host channel by interfering 
with its communication. More formally, in a top-level characterization of covert channels, Kemmerer [11] states 
that necessary conditions for the existence of a covert channel are: the presence of a global resource to which both 
the sender and the receiver have access, a means of modifying that resource, and a method of synchronization 
between the receiver and the sender. 

The topic of covert channels has received considerable attention among researchers in secure system design 
and secure source code design [14], [7], [6]. Existing results on covert channels can be divided into two major 
categories, storage channels [18] and timing channels. Moskowitz and Kang [14] define a storage channel as a covert 
channel where the covert symbol alphabet consists of asynchronous responses of a global resource (ACK/NACK 
responses from a processor, success/failure of a packet transmission). Shieh [17] models covert channels as finite 
state graphs to estimate the bandwidth (bit/s) of a covert storage channel. A covert timing channel encodes by 
modulating the time intervals between successive responses [14], [7], [10]. The capacity of timing channels was 
investigated by Anantharam and Verdu [2]. Subsequently, the capacity of covert timing channels was investigated 
by Giles and Hajek [7], where the authors consider the time interval information between successive transmissions 
of packets from a queue as a timing channel. They model this channel as an information-theoretic game between an 
illegitimate user who attempts to modulate these inter-arrival times and a 'jammer' who introduces random delays 
in the transmitted packets to arrive at bounds on max — min and min — max rates of mutual information in covert 
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timing channels. 

In the context of an ALOHA channel, the authors in [6] consider jamming based communication over a slotted 
ALOHA channel, where an FCFS based splitting algorithm is used for contention resolution [19]. They consider 
a scenario with a large number of users (with the aggregate arrival rate being Poisson with rate /i packets per 
slot), and develop two protocols for jamming based covert communication. In the procedures developed in [6], 
the illegitimate transmitter communicates by means of influencing the number of collisions that occur within the 
contention resolution period, and the illegitimate receiver uses a maximum likelihood decoder to determine the 
number of collisions caused by the illegitimate transmitter. They demonstrate through numerical methods that the 
ALOHA system can support persistent interference by the illegitimate user (using the procedures developed in [6]) 
without causing user packet backlogs to drift to infinity, only if the multi-access channel is lightly loaded (/i « 0.1). 



A. Main Contributions 

In this paper, our focus is on the fundamental capacity limits of the covert ALOHA channel over the class of all 
ergodic jamming strategies. 

• We study the information-theoretic capacity of the illegitimate system where n legitimate users (where n is 
any finite number) communicate over a slotted ALOHA channel, and for any fixed offered load a E (0, 1), 
subject to a stability constraint on the legitimate user queues. We first derive achievable jamming rates over 
the slotted ALOHA channel by considering various i.i.d. jamming strategies, and where the illegitimate user 
has varying degrees of side-information on the channel state. 

• We derive an upper bound on the jamming capacity of this channel over the class of all ergodic undetectable 
(to be defined) strategies, subject to stability constraint on the legitimate user queues. The dynamics of this 
system are complex because the jamming strategy of the illegitimate user influences the queueing dynamics 
of all the legitimate users, thus coupling the source (illegitimate user) and the channel state (the queue lengths 
of all the users). We also show that this upper bound is tight as the offered load approaches unity. 

To obtain an upper bound, we first decouple the state of the illegitimate channel from the jamming strategy by 
considering a virtual parallel channel (which is stochastically coupled with the true channel) along with a pair of 
virtual illegitimate users. However, our construction is such that the dynamics of the virtual illegitimate users do 
not modify the dynamics of the virtual channel. Using our construction, we prove that the capacity of this virtual 
illegitimate channel is always greater than that of the true illegitimate channel and then bound it as a weighted sum 
of the capacities of a codeword-weight constrained Z-channel and a rate 1 error free channel. 



Further details on our communication system model are given in the next section. In Section III we present 



the achievable rates for jamming-based communication for a two-user system. In Section IV we develop an upper 
bound on capacity in the context of a two-user system, and provide numerical results. We generalize the results to 
the n user case in Section [V] 
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Fig. 2. The Illegitimate Cliannel 



II. System Model 

In our model, we first consider the case where two legitimate users and two illegitimate users (Alice and Bob) 
share the common medium using slotted ALOHaQ Alice wishes to transmit to Bob without being detected by 
the system. Each legitimate user in this slotted ALOHA system is associated with a queue, with independent and 
identically distributed (i.i.d.) Bernoulli packet arrivals to each queue at rate A. 

A slotted ALOHA system with two legitimate users Qi and Q2 is shown in Figure [T] With a slight abuse of 
notation, we will use Qi, i = 1, 2 to denote both the users and the corresponding length of their queues. When the 
queue Qi is non-empty. User Qi attempts to transmit in a time-slot with probability p. A time-slot j is said to be 
active if at least one of the users transmits a packet on the channel. 

Collisions naturally occur in this system when both users Q\ and Q2 attempt transmission. In a regular slotted 
ALOHA system, such a collision is detected, and the colliding packet is then retransmitted. 

We assume that the legitimate users do not care for the packet collisions so long as their buffers do not overflow 
(strictly speaking, as long as their queues do not become unstable). The legitimate users do not know how many 
legitimate users use the system, therefore as long as their buffers don't overflow, they consider the collisions 
natural. They are guaranteed by a system administrator that their buffers will not overflow under the offered load. 
If a legitimate user's queue becomes unstable, then (s)he complains to the system administrator, who then starts a 
search for potential illegitimate users. Alice and Bob have to exploit this feature to remain undetected: that is, Alice 
should not jam packets indiscriminately which would make the system unstable. We show that in this scenario, 
there is a nonzero capacity for the illegitimate channel. 

Alice exploits this aspect of the system to communicate while remaining undetected, choosing signals from 
a binary alphabet {'0','!'}. For every '1' that Alice wishes to transmit, she causes a collision by jamming 
a transmission in the corresponding time-slot. Throughout this paper, we will distinguish between the terms 
collision and jamming according to the following convention - by collision, we will mean that an attempted packet 



'We consider the generalization to the n user case in Section V 
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transmission by either user Qi or user Q2 is not successfully received; whereas, a time-slot that is active is said to 
be jammed if Alice transmits a ' 1 ' in that time-slot. 

In order for the illegitimate users to remain undetected, Alice should be able to (causally) detect the presence of 
a legitimate packet on the channel. This can be achieved by carrier sensing or power-level detection. In practice, 
there exist protocols, e.g.. Carrier Sense Multiple Access with Collision Avoidance (CSMA-CA) that require the 
transmitter to sense the carrier signal from other transmitter(s) before starting their own transmission. Also, there 
are commercially available cognitive radio products that sense if a particular channel is busy or not before and 
during its use. We idealize this situation and assume that the illegitimate transmitter can, with probability 1, detect 
the presence/absence of a legitimate transmission. 

The illegitimate receiver (Bob) interprets each unsuccessful packet transmission as a '1' transmitted by Alice, 
and each successful transmission by the legitimate users in the system as a '0'. Neither Bob, nor the system 
can distinguish between collisions amongst the legitimate users and transmissions that are jammed by Alice. This 
indistinguishability is essential for Alice's communication to remain hidden. If Bob were granted the ability to learn 
to distinguish between jamming and collision, so could the legitimate system, thus exposing the illegitimate user. 

Further, Alice's jamming strategy must not make the overall system unstable [2]. In other words, Alice's jamming 
strategy should be such that the queue lengths of the legitimate users should not go to infinity (a more formal 
description is provided in ([3]l). Alice's jamming policy is illustrated in Figure |2] The shaded time-slots in Figure |2] 
correspond to idle states when there is no activity by the legitimate users of the channel, while the solid black 
time-slots represent collisions in the system. 

Let 

Mi ~ /{channel is active in time-slot i}, (1) 

where / is the indicator function. Thus, Mi = 1 if at least one of Qi or Qi transmits a packet over the common 
channel, and Mi = otherwise. For each T e Z+, we define the active set 

At(}^) = {i:l<i<T,Mi = 1} (2) 

to be the random set of active time-slots; the uj in the definition indicates that this is a random set that depends 
upon the queue states and the attempt probabilities at each of the legitimate user queues. However, for ease of 
notation, we shall drop the oj in subsequent references to this random set. 

The active time-slots are indexed by the function t{i) — infjfc > 1 : \Ak\ = i} which denotes the time-slot when 
the channel is active for the i-th time. The illegitimate channel is defined as the jamming channel between AUce 
and Bob. Note however, that the codewords used by Alice over this jamming channel are only transmitted (and 
received by Bob) over consecutive t(i)'s. 

For the purpose of rigor, assume that whenever the channel is idle, Alice transmits a <j). Thus, Alice's codewords 
are strings from the alphabet {0, !,(/)}. Next, we will define Sao as the set of codeword strings of infinite length 
that Ahce can use to jam over the illegitimate channel so that the queues Qi,Q2 are stable and ergodic. Formally, 
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x°° G Soo are such that for each (fc, I) e Z^, and each sample path ui, the hmit 

1 ^ 

lim -5^J{(Qi(i),Q2W) = (fc,0}H (3) 

converges to a well-defined probability measure over Z^, where Qi(«),Q2(*) denote the queue-lengths at time i. 

We then define the projection (truncation) operator P„j operating over all strings x" of length n > m such that 
Pto(x") is a string of length m satisfying 

(x™), ^ (P„(x")),, VI < i < m. 

where (a), is defined as the i-th element in vector a. 

Formally, let 5*7- be a set of T length strings derived from Soo under the projection operator so that for all 
x'^ e St, 3x°° g 5oo, such that x^ ^ Pt(x°°). 

We can now define the (ergodic) information-theoretic hidden capacity over the active time-slots as follows: 

C(5) = liminf sup ;^/(x^;y^) (4) 

where the codeword vector x^ = {xi,X2, ■ ■ ■ , xt), each Xi € {0, 1, 4>} transmitted by Alice is received by Bob 
across the hidden channel as y^. The notion of the constraint sets is crucial to our definition of hidden capacity 
since Alice and Bob need to ensure that they remain hidden by coding such that the legitimate users are not infinitely 
backlogged. 

Recall that we considered the </> alphabet to denote that Alice does not transmit anything over the timeslot 
corresponding to cj) since the channel is idle at those timeslots. Bob realizes that the channel is idle and does not 
expect transmission by Alice. Hence the capacity in Equation Q is 

C(5)=liminf sup -/(x'^^l ; yl^^ |) (5) 

where x'"^^' = a:^t(2), ■ ■ ■ :^t{\AT\)) ^t{i) G {0, 1} is the effective codeword vector transmitted by Alice and 

received by Bob as y''^^'. We shall use this definition of capacity in the rest of this paper. 

This paper derives analytic expressions that upper and lower bound the capacity of this illegitimate system. This 
capacity is less than one bit per transmission because the channel between Alice and Bob is not ideal. An error 
in Bob's interpretation occurs when there is a collision amongst the legitimate users in the system. A collision 
amongst legitimate users can only occur when more than one of them has a packet to transmit. Thus, conditioned 
on the event that multiple users have packets to transmit and that there is activity in the channel, the hidden channel 
between Alice and Bob behaves as a Z-channel [4], [9] (see Figure |3]l. 

We assume that the illegitimate users know the offered load a = A , where p = 1 —p, and the Z-channel crossover 
probability pc- The justification for this assumption is that if the illegitimate users do not know the offered load 
and start jamming with probability 5, then no matter how small this 5 is, there's the possibility that the system 
becomes unstable and the illegitimate users are exposed. 
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When only one of the two legitimate users has packets, there are no collisions in the legitimate channel, and 
the illegitimate channel reduces to an ideal error-free channel. When none of the legitimate users have packets, no 
transmission is possible. 



III. Achievable Rates for the Hidden Channel: The Two User Case 



A. Capacity 



The hidden channel is source dependent because the jamming strategy modifies the queues Qi,i = 1,2. It also 
has memory, and is constrained to ensure that the legitimate system remains stable. Conventional single letter 
characterizations for capacity (used for discrete memoryless channels) cannot be used in this context and hence a 
closed form expression in terms of channel parameters is difficult to obtain. The next sections investigate achievable 
rates for this channel under i.i.d. jamming strategies, and an upper bound is then used to motivate this i.i.d. jamming 
strategy. 

B. I.i.d. Jamming Strategies 

We define the following sets 5-0,2 = {(Qi = 0, Q2 = 0)}, 5i,i = {{QuQ2) : Qi = 0, Q2 > 0} U {(Qi,Q2) : 
Qx > 0, Q2 = 0} and 52,0 {{Q11Q2) ■ Qi > 0, Q2 > 0}. In other words when k of the 2 queues are 
backlogged, the process {Q1Q2) is said to be in state Sk,2-k- When the queue length process (Qi, Q2) G 6*2,0 and 
the channel is active, the illegitimate channel reduces to an equivalent Z-channel (see Figure [3]), while for states 
(Qi,Q2) G Si^i when the channel is active, the illegitimate channel reduces to a zero-error channel. 

We first consider the system model as is and derive a lower bound on the capacity. We then provide the illegitimate 
users with side information so that they know the queue state process ((5i,(52) completely. 

Let us denote the channel state in a time-slot i by S"*. We consider coding/jamming policies described by a 
map n : C ^ [0, 1] where C is the set of channel states. Alice, then jams (i.e. transmits a '1') a transmission in 
an active time-slot t{k) when the channel is in state S*''^^^ e C with probability /i(S'*'^'^)) independent of all other 
events. In other-words, given the channel state, Alice uses a codebook that has been generated in an i.i.d. manner. 
Consequently, the expression for capacity achievable over such i.i.d. strategies follows from Equation (jSj) as 



Observe that since the arrival rates at the queues are Bernoulli, the transmission attempt probabilities of both users 
are i.i.d., and Alice's coding strategy depends only on the current queue state independent of all other events, the 
queue length process (Qi, (52) is a Discrete Time Markov Chain (DTMC). Consequently, the hidden channel can be 
defined as a time varying channel where the channel states {S'i,2-j},« G {0, 1,2} follow a hidden Markov process. 
The complete transition matrix of this DTMC can be derived to show that the DTMC is aperiodic and positive 
recurrent for A < pp. 

Mutual information rates of finite state Markov channels have been studied in [15], [8] for the i.i.d. coding 
case. A formula for mutual information for any regenerative stochastic process (including, in particular, for hidden 



C {S) = lim inf sup 




(6) 
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Markov inputs over a countable- state space Markov channel) is provided in [16]. However, the formula in [16] 
can only be numerically computed. In the following subsections, we derive closed-form expressions for each of the 
cases discussed above. 

1) Coding strategy 1: The illegitimate users know that the hidden channel is an arbitrarily varying time-varying 
channel which is composed of a Z-channel (with known crossover probability Pc) and an error-free channel. Also, 
note that to retain the stability of the legitimate user queues and hence remain undetected, Alice cannot jam packets 
indiscriminately, but has to ensure that no more than a certain fraction j3 of the packet transmissions are jammed. 
Since Alice does not have channel state information, she employs the policy /x(S'*^'^^) — q, for all active time-slots 
t{k). In other words, Alice uses a state-independent i.i.d. jamming policy with jamming probability q. 

Since the queue length process (Qi,Q2) is a Discrete Time Markov Chain (DTMC), we can solve the global 
balance equations and sum over the probabilities of the relevant states to arrive at the following steady state invariant 
probabilities for the illegitimate channel, 

where q = \ — q. Further, with this i.i.d. jamming strategy, the stability constraint leads to the inequality q < (3 
(recall /3 is an upper bound on the fraction of transmissions that can be jammed). We can now calculate (3 from 
the global balance equations in terms of the offered load a = \/pp of the queues as follows, 

(3^1- a. 

to ensure that the < 'Ki^2-i < 1 for i e 0, 1, 2 in Equation (jTji. 

Hence the state-independent i.i.d. coding strategy for Case 1 is to find the optimal value of q. To obtain an 
expression for the capacity of this arbitrarily varying channel, we will first decompose the channel into two states 
5i 1 and S'2_o and calculate the channel capacities for a channel fixed at each of these states. Note that we exclude 
the state 50^2 since there are no active time-slots in when the channel is in this state. 

We define the channel-state dependent active time-slots ' — /(at least one of the users transmits in time-slot 
fcjS''"' = S'i^2-j)- Analogously, we define A^'^ — {k : M^*'^ = 1} to be the active time-slots when the channel 
is at state Si^2-i- 

Accordingly, define 



^ \At\ 

Ci,2~i{S) = liminf sup - V I{xt(,,y,yt(k)\S*^^^ = 5',,2-i) 



to be the i.i.d. coding capacity of the channel fixed at state 5i_2-i- Here the constraint set St = {x''^^' : m(xl'^^l) < 
[3At}^ where m(xl'^^l) is the number of '1' symbol^in the vector x''^^'. 

-We henceforth denote the number of '1' symbols in a codeword as the Hamming weight of the codeword. 
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The illegitimate channel, given channel activity, is a zero-error channel at state 5*1 1. Observe that 

P(Mf = 1) = p. 

Hence, from the strong law of large numbers, 

lim = p. 

T^oo T 

Thus Cia = l.p = p- 

In order to determine €2,0, we first derive the expression for the capacity Cz{P,Pc) for a Z-channel with binary 
codeword^ constrained such that the number of '1' symbols be less than or equal to N(3, and crossover probability 
Pc- From [9], the rate Rz{u,pc) of the Z-channel with cross-over probability Pc for i.i.d. codes of Hamming weight 
Nu is given by, 

(u, Pc) = H{up,) - uH{pc) (8) 

which is maximized at 

_ Pc 
Umax — 



l+Pcp'c^^''^ 



where pc = 1 — Pc- Also, Rz{u,pc) is monotonically increasing for u < Umax and monotonically decreasing for 
u > Umax- Thus the i.i.d. achievable capacity under the constrained Hamming weight condition for Alice is 

C,{P,p,)^H{^p,)~-fH{p,) (9) 

where 7 — miii{umaxi P)- The optimality of i.i.d. coding for the weight constrained Z-channel follows by using 



similar steps as in Equations ( 24 1-( 27 1 



When the illegitimate channel is in state ^2.0 and the legitimate channel is active (with probability P{M^^'^^) — 
1 — p^), the corresponding channel has the capacity of the Z-channel under the weight-/? codeword constraint — 

thus C2,0 = C,(/3,Pe)(l-p2). 

Then following the method outlined to derive the capacity for Arbitrarily Varying Channels from [5], we have 
Theorem 1: The hidden-channel capacity is lower-bounded as, 

C > C,(/3,p,)((l-p2)^2,o + 7ri,ip). (10) 
Proof: Since the Z-channel has lower capacity than the zero-error channel, the optimal codebook for the Z-channel 
can be used over a channel switching between the Z-channel and zero-error channel to achieve rate Cz{P,Pc)- Note 
that this codebook is transmitted only over the active time-slots which exists ((1 — p^)tt2.q + t^i^ip) fraction of the 
time. Hence the total rate is thinned by this fraction. ■ 

^Note that we consider the Z-channel only over the active time-slots, thus we restrict the alphabet to the set {0,1}. 
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2) Coding strategy 2: The illegitimate users know that the offered load is a = A, where p ~ 1 — p, and the 
Z-channel crossover probability is pc- Since the Z-channel crossover probability is given by 

1 - p2 2-p 



Pc = T^= 7^^^ (11) 



the illegitimate users can compute 



P=T~Z — • (^2) 

1 +Pc 



Also, since A — ap{l — p), the illegitimate users can compute A, the arrival rate for the user queues Qi. 
Theorem 2: The hidden capacity C can be lower bounded by, 

C > max i?,(g,^2,oPc)(l-p2)- (13) 

0<q<P 

Proof: Assume that Alice has a large interleaver present at the transmitter output and the Bob has the correspond- 
ing de-interleaver before the receiver input. Now the composite channel consisting of the interleaver, the illegitimate 
channel and the de-interleaver will be in state 52,0 with probability 7T2fi and will have a crossover probability of 
Pc given that the channel is in state 82,0- Therefore, this composite channel may be considered to be a uniform 
Z-channel with crossover probability pi = Ti2.oPc with rate Rz{q,pl) where q is Alice's jamming probability. (Note 
that 712.0 ™d therefore p^, depends on q and that we must have q < f3 as before to ensure stability of the legitimate 
user queues.) The result follows by maximizing Rz{q,pl){l —p^) over q. The extra factor (1 —p^) appears because 
the hidden channel is available only for this fraction of the total time. ■ 

Remark: Coding strategy 2 is better than coding strategy 1. This is because (1 — p^) > p, 'iTi,2~i < 1 and 

C^{f3,Pc) maxo<g</3 i?2(g,_Pc) < maxo<,</3 7r2,oPc)- 

3) Achievable rate in presence of side information: In the case where complete channel state knowledge is 
available to Alice, an alternate lower bound can be derived. Consider a coding scheme where Alice uses separate 
codebooks for each channel state. Let the probability of Alice transmitting a '1' in state 6*2,0 be q as before, while 
the probability of Alice transmitting a '1' in state 5*1,1 be w. Finally, Alice does not transmit in the inactive queue 
state of 5*0.2- In other words, for each active time-slot 

= ^^^^ ^° (14) 

[ w if S'C^) = Si,i 

Using the same arguments as in Section [Hi] steady state probabiUties of the queues can be calculated as, 

7ro,2 = \ PiQi ^ (15) 

p(l — w) 

TTi.i = 2 fl- A) (l-P(Qi = 0)) (16) 



where 



ppq, 

7r2,o = 1 ~ 7ro,2 - 7ri,i (17) 



PiQi = 0) = (1-w) {-p + p^ {l~q)+pq+{l-p) pa) 

p^ (1 - g) {I ~ w) + {1 — p) p {q — w) a + p {1 — q) (—1 + w + {1 — p) pa) 
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Then the hidden rate can be simply seen to be the sum of the rates of the Z-channel and the zero-error channel 
weighted by the probabilities that the illegitimate channel is in these states. The rate can then be maximized over 
possible values of q and w so as to retain the stability of the steady-state queue lengths at the legitimate users as 
follows: 

Theorem 3: The achievable rate of the illegitimate channel as described in Section over all i.i.d. jamming 
policies over a legitimate channel with attempt probability p and offered load a, with complete channel state {Si^2-i) 
information at the sender and receiver is given by: 

C2{p,a)> max Tr2.o{l - p'^)Rz{q,Pc) + T^i.ipHiw). (18) 

0<q<l — a, 0<iv<l — a-\-pa 

IV. Upper bound on Hidden Capacity: The Two User Case 

Upper bounds on capacity allow us to gauge the usefulness of the achievable strategies (namely i.i.d. coding) 
presented before. As detailed before, the channel between Alice and Bob is source dependent and has infinite 
memory. Thus, obtaining a good upper bound is difficult. In this section, we derive an outer bound on the hidden 
capacity of this system over the set of all er^oc/Zc jamming policies that Alice may employ. This ergodicity constraint 
on Alice's policy renders the problem tractable, and allows us to use relatively simple mathematical tools to arrive 
at upper bounds. To obtain an upper bound, we first decouple the state of the illegitimate channel from the coding 
strategy by considering a virtual parallel channel. We then prove that the capacity of this virtual illegitimate channel 
is always greater than that of the true illegitimate channel and then bound it as a weighted sum of the capacities 
of a Z-channel and a rate 1 error free channel. 

Theorem 4: The hidden capacity C* for a slotted ALOHA system described in Section|ll]achievable using ergodic 
jamming can be upper bounded as, 

V \-pa ) 

where Cz{f3) is the capacity of the Z-channel with crossover probability pc — P^/(l — P^) using codewords 

constrained to have no more than (3 fraction of I's, with 

- 1-pa {l-p)a^ 

(i = l-a + . 

(i — pja'^ i — pa 



Proof: Consider a virtual channel {Q'i,Q2), defined as a stationary and ergodic process, so that {Ql,Q2) = 
(Qi,Q2)- In other words, for every legitimate packet transmitted over the true channel, there is a virtual packet 
transmitted over the virtual channel Let us assume that Cindy wishes to communicate with Doug secretly by 
jamming over this channel {Ql,Q2), but that Cindy's transmit policy (jamming/not jamming any active time-slot) 
does not affect the dynamics of the queues. More specifically, if, in a particular time-slot, exactly one of the two 
legitimate users, say user 1 (in the original system) transmits a packet and Alice chooses not to jam, then whether 
or not Cindy jams it on the virtual channel, user 1 does not have to transmit that packet again. If Cindy chooses 
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Fig. 3. The Traditional Z-Channel 



to induce a collision, Doug sees a collision in this time-slot and decodes it as a '1'. Similarly, if Alice jams a 
packet on the real channel, then whether or not Cindy jams it on the virtual channel, that packet is retransmitted by 
the respective user(s) on both the real and the virtual channels. However, the bit understood by Doug will depend 
upon whether there was a colUsion on the virtual channel. Hence, by construction, we couple the dynamics of the 
queues Ql and to those of the queues Qi and Q2 which are governed by mutual collisions, transmissions and 
jamming over the real channel (over which Alice and Bob communicate). 

Let Alice's optimal ergodic strategy be A*, which leads to a hidden capacity of C*. From the ergodicity of 
A* this results in steady state probabilities 7r*2_j,i € {0,1,2} corresponding to states Si^2-i,i S {0,1,2} for 
(Qi, Q2). and by our coupling construction for (Q*, Q2) as well. Not only can Cindy repUcate AUce's strategies, 
but since she can choose from a wider set of coding strategies (since that does not affect the dynamics of the virtual 
channel), the capacity that Cindy can achieve C*>C*. 

Although the codewords in A* might span across different states in general, the ergodicity constraint on the 
optimal poUcy impUes that the fraction of time-slots jammed by Alice in each state 5j,2-i converges to a constant 
Pi,2-i defined as 

1 " 

(3f 2-i — 1™ ~/ ^{^ = 5*1 2-i}-'^{channelis active at time-slot A;}/{Alice transmits a '1'} 
' n— >(X) n ' 
k=l 

where /{} is the indicator fimction and as before, 5* denotes the channel state at time-slot t. Consequently we 
will apply the same codeword weight constraint (3* 2-i to the state-dependent code that Cindy uses to communicate 
over the virtual channel at each state Si^2-i- 

Further, note that given queue state information, the Cindy-Doug illegitimate channel is a discrete memoryless 
time-varying channel with state side information at transmitter and receiver. 

Consider a (2"^, n) code X" = {xi{w)}^ over the ternary alphabet {0,1,^} transmitted over this channel with 
source alphabet W corresponding to a state sequence (trajectory) S" = {5*}", 5' e {Sk,2-k,k e {0,1,2}} and 
received sequence Y" = {yi(w)}i . Then following [20], we can define Cc to be the capacity of the Cindy-Doug 
channel and C'i,2-i(/3*2-j) to be the of the Cindy-Doug channel fixed at a state Si^2-i under codeword constraint 
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Pi,2-i as 

Cc = liminf sup -/(W^;Y",S") (20) 

and 

C,.2-,(/?;2-<) = liminf sup - V yt(fe)|5*W = 5,,2-.) (21) 

fe=l 



respectively. We will now express the capacity of the Cindy-Doug channel Cc in terms of the individual Ci^2-^i{(3*2^i) 
values. 
Note that 

nR < /(Vr;Y",S") (22) 

= /(T4^;Y"|S") +/(VK;S") (23) 

< /(X";Y"|S") (24) 

= i7(Y"|S") -i7(Y"|X",S") (25) 

n n 

< (26) 

n 

< ^/(x,;y,|^*). (27) 

i=l 

The inequality in ( [24| follows from the assumption that the source and the state sequence are mutually independent, 
so I{W; S") = 0, and the data processing inequality. We have inequahty p5| ) as a consequence of the discrete 
memoryless nature of the channel and the inequality i?(Y"|S") < J^^^i -^iVil^'^) — ^iVil^^)- Also 



observe that /((/); 01 S"*) = 0. Dividing both sides of (27 1 by n and using the ergodic strong law of large numbers 
and the definitions in Equation pT) , we arrive the following bound for the capacity of the overall system with 
Cindy communicating to Doug: 

Cc<Y. C^a~^{Pl2-i)<2-^■ (28) 
i,2-i 



We note that a similar expression as ( 24 1 is given as part of the converse proof of capacity for asymptotically 
block memoryless time varying channels by Medard and Goldsmith [12]. We note in passing that the sum rate 



in Equation (28 i can be achieved by Cindy switching between codebooks corresponding to the capacity achieving 



code for each state S'i.2-j without affecting the channel process {Qi, Q2) and hence the inequality in Equation (28 1 
can be replaced by the equality. 

Next, we obtain outer bounds for C2,o(/32o) and TTjg. Recall that for each T, A^''^\uj) — {i I < i < 
T, Mj^^'*'-' — 1}. From the strong law of large numbers, we have that 

Observe that our system model implies that for any 1 < j < T, a transmitter Cindy, transmitting to receiver Doug 
over the illegitimate channel conditioned on the event that the legitimate channel exists in state 5*2.0^ can choose 
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to jam a packet (i.e. transmit symbol '1') if and only if j e Ai^'^K Further, given that we are already in state 
the jamming set A^'""* is independent of the jamming policy (codebook) employed by Cindy. 

Now, for any j G A^''^^ observe that the illegitimate channel (between Cindy and Doug) is a Z-channel with 
crossover probability pc, where pc = jzrps- Thus by concatenating the time-slots in a!^'^^ (and ignoring {1 < j < 
T}\A^''^') and employing a Z-channel coding strategy over A^^-°\ it follows that for any e > 0, 3T large enough 
such that, ^^^^ 

where Cz{P2 0) '^he channel capacity of a Z-channel with weight constraint P2 q. For the Z-channel, it is well known 
that i.i.d. coding maximizes capacity [4], and hence the rate in state ^2.0 is upper bounded by (1 — p^)Cz{(32 o)- 
In state given that there is activity in the legitimate channel, the channel behaves like an ideal channel (thus 



a trivial upper bound on Ci^i{f3l i) is 1), and the maximal rate in S'0,2 is zero. Thus, using (28 1 the upper bound 
on C* can be rewritten as 

C* <C,< {l-f)Cz{PloM,„+p7r* (29) 



Further (see (47i in Appendix), we have q > 1^2.0, where 7r2,o is the steady-state probabiUty that both user 



queues have packets when no jamming is applied. From straightforward computations, we have 

f 1 - p) 

7r*2,>n2.o^ ^\ ^' . (30) 
I ~ pa 

Hence, 

7rt_i < 7rJ_i + TTo 2 < 1 - 7f2,0- (31) 

Thus, we have that 

f 1 - n) o? 

< 1 < 1 - ^\ ^' . (32) 

1 — pa 

The value of (32 q depends on the strategy A* that Alice chooses, however we will upper bound it by /Jj ^ 
as follows. From our assumptions of ergodicity and stability of the legitimate user queues we have that 

7VA < Nppwlail ~ Plo) + Npnl^ 

< Nppirlail- |3l„) + Np{l-^t2,o)■ 



Thus, using the value of 7:2^ from Equation (30i, we can upper bound P2 t>y 



/32*o</5=l-^A^ + ^-^2,o (33) 
ppnl„ n2fi 



The result now follows by observing that ttj q < 1, Equations (31 1, and (29 1. ■ 
We present numerical results for the achievable bound and compare it against the upper bound in Figures |4]-^ 
The upper bound is loose everywhere except at values of a very close to 1 . Observe that the bound is asymptotically 
tight in the sense that as the offered load a 1, both the upper bound and the achievable rate tend to 0. 

The bound also improves with smaller values of the transmission attempt probability p. These observations can 
be explained by noting that we have bounded ttj q by 1 in the (/3) term of the upper bound. For smaller attempt 
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probabilities, is closer to 1, even when the normalized load a to the queues is small. As p increases, the queues 
at Qi and Q2 are cleared promptly and hence the value of ttJ q is much less than 1. 

V. Hidden Channels with n legitimate users 

Consider n legitimate user queues over a common collision channel, each with homogeneous (Bernoulli) packet 
input rate A. In this section we present an asymptotically (in offered load) tight upper bound to the channel capacity 
of the illegitimate users as a generalization of the results in Sections |in] and |IV] 
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A. Achievable Rates: The n User Case 



As reasoned in Section III while the illegitimate channel depends on the state of the queue, the capacity is 
affected by the number of queues among the n users that have packets to transmit in their buffers. For a state 
where k of the n users have packets in to transmit (non-empty buffers), we define the crossover probability of the 
corresponding Z-channel as 

It follows that p"c < p'c^'ik G {1, 2, . . . n}. Correspondingly, we define TTk.n-k to be the steady state probability 
of the channel being in any state Sk.n-k where k users out of n have packets to transmit. Note that for each of the 



three cases of increasing illegitimate user side-information in Section III-B the achievable rate calculation follows 
the same techniques as for the two user case. Due to constraints of space, we merely present the expressions for 
the n user case with comments where necessary. 



1) Coding strategy 1: Recall from Section III-B that the illegitimate users know the offered load 



at each legitimate user and assume that the channel is a time varying Z-channel with given crossover probability 
Pc- The hidden-channel capacity can then be bounded as 

n 

C>C,(/3„,Pe)5I(l-p')^fe,"-fc (35) 
fe=i 

where f3n = I — an. 

2) Coding strategy 2: In this case, the illegitimate user views the channel as a composite Z-channel with effective 
crossover probability 



fc ^ T^k.n-kp'''' 
k=l 

resulting in an achievable rate of 



Pc = 2^ T^k.n-kVr (36) 
fc=l 



C>^max R,{q,p,){l~r)- (37) 

3) Achievable rate in presence of side information: We define the illegitimate user jamming probability vector 

q = ((7i, q2, ■ ■ ■ Qn) where qk is the probability that Alice jams a transmission when the system is in state Sk.ji-k- 
Then, the achievable hidden rate under i.i.d. strategy in this case is, 

n 

Cn{p,a)= max V 7rfc.„_fc(l - (38) 

q:Vfc, ,r,, „_i.el0,ll, ^ ' 



B. Upper Bound: The n User Case 



Analogous to the proof in Section IV we define a weight constraint (3^ ^ j, that applies on codewords that 
Alice (and therefore Cindy) can use for the n user case. The values of ^ j, depends upon the optimal strategy 
that Alice uses. However, we shall upper bound them as in the previous section to obtain an upper bound for the 
capacity. 
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The corresponding Z-channel capacities are denoted by Ci''\p^ ^_^.). We trivially bound Pk,n-k < 1 for all 



k < n. For sake of uniformity of notation fix ci°'' — and cl^'' — H(l) — 1. Also, following Equation (28 1, the 



capacity of the overall channel with Cindy communicating to Doug is bounded by 

n 



k=Q 



For the general case of n legitimate users, the Markov chain of the states of the queues of all the legitimate users 
is n-dimensional and therefore difficult to analyze. Hence we bound the values of tt^. ^, for any transmission 
strategy by Alice. Consider the probabilities Ttk,n-k denoting the steady state distribution of the queues without the 
presence of any illegitimate user Using the same reasoning as ( [47| we have that 

<,0 > T^n,0 (39) 



yi < n 



Solving the global balance equations for 7r„ o, we have 



PP 



n~l 



n -1 



Also, since 



we have that. 



A(l - (n - l)pp"-2) 

n 



(40) 



(41) 



3=0 



k=0 



We now bound /3* q in a technique similar to that used in Section IV Observe that for stability we must have that 



A<E<-v 



PP 



Trivially bounding /3*_j j's for i > by 1, and using the inequalities in Equations (39i, we bound 



(42) 



Thus Alice's hidden capacity is bounded by, 

C < Cc 

n 

< Y.7Tk,n^kCi'^HPln^k)ii - P") 



k=l 
ri-1 



< E ^.n-kCi"^ + <,oCi"H/3;o)(l - P") 
k=0 

< (l-7f„,o) + Ci")(;9„)(l-p") (43) 
Theorem 5: The hidden capacity C'"', for a slotted ALOHA system described in Section |ll] with n legitimate 



users, achievable using ergodic jamming can be upper bounded as. 



< 1 



PP 



A(l - (n - l)pp"-2) 



+ C(")(^„)(l-p") 



(44) 
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where C^\l3n) is the capacity of the Z-channel for codes constrained to have less than /3„ fraction of 'I's in each 
codeword corresponding to a crossover probability of p'c^ . 



Proof: Follows from the inequalities (41 1 and (43 1 



Observe that as the offered loads approaches unity (i.e. as A ^ pp" ), each 'Ki.n-i for i < n in Equation 



(42 1 while 7r„,o 1- Thus /3„ and hence ci"''(/3„) 0. Hence C* converges to as the load approaches 1, 



and is thus asymptotically tight to the i.i.d. coding rate for the n user case. 

VI. Conclusion 

The setting studied in this paper is of two illegitimate users - a transmitter and a receiver, communicating with 
each other by exploiting the resources of a slotted ALOHA system. The illegitimate pair communicate by jamming 
legitimate transmissions while striving to remain undetected by the legitimate slotted ALOHA system. In this paper, 
we find that a closed-form characterization of the information-theoretic capacity of the illegitimate communication 
system is extremely difficult, and hence find lower and upper bounds on capacity. We employ i.i.d. coding strategies 
under varying side-information assumptions to determine lower bounds. Next, we employ constrained decoupling 
arguments to determine upper bounds, and finally, we compare the upper and lower bounds. We find that, in the 
limit when the offered load tends to unity (and the capacity to zero), our upper and lower bounds coincide. 

Appendix 

Consider two sets of queue length processes (Qj^, Q^) and (Qf , Q'D, with identical arrival processes A^{n) = 
A'l{n), k = {1,2}, to each queue over any fixed interval of time-slots n ~ 1,2, . . . , N, and with identical initial 
state (i.e. Q'({1) — QY {^) ™d Q2{^) — ^2^(1))- The process corresponds to the scenario where two 

users compete to access a shared (slotted) channel and no illegitimate jamming occurs over this channel. In other 
words, collisions occur over this channel only due to simultaneous attempts due to the two legitimate users. On the 
other-hand, {Q^, Q^) corresponds to the scenario where two users compete to access a shared (slotted) channel and 
illegitimate jamming occurs over this channel. Thus, collisions could occur over this channel either due to collisions 
by these legitimate users, or due to a jammer (Alice) who could employ an arbitrary jamming strategy. At each 
time-slot, for either scenario (with or without jamming), we assume that each of the user attempts to transmit 
independently with probability p, irrespective of whether the queue has packets or not. Note that when the queue 
is empty, a decision to attempt does not affect the system dynamics. However, this enables us to sample-path-wise 
couple the two queueing systems. 

Consider any system sample path corresponding to a sequence of arrivals and transmission attempts (which are 
identical to both (Qi'jQl^) and {Qi,Q2))- We first show that for all n, we have 

QYin) < Q({n) 

(45) 

Q^in) < QUn). 



We see this by contradiction. Let / + leN, l</<iVbe the first time slot where ( |45] l fails. In other words, 
Qiil) < Qi{l) Qiil) < Qi{l) and QY{1) < Qi{l), but (without loss of generality, say) + 1) > Qi{l + 1). 



18 



Since arrival and transmission attempts are identical in both the jammed and the unjammed queues, if queue Q( 
transmits a packet successfully (i.e. no collision occurs) the same should be true for queue QY ■ Thus, QY {1+ 1) — 
QY{1) + A^{1 + 1) - I{QY{1) > 0} and Q({1 + 1) = Q({1) + A-'{1 + 1) - I{Qi{l) > 0}. However, since 
QYil) < <3i (0' HQiil) > 0} < /{Qi (0 > 0}, we have (l + 1) < Qiil + 1) which leads to a contradiction 
of our hypothesis. Thus ( |45] l is true for all n. 

The relation 

N N 

E (") > 0' Q2i^) > 0} > E > 0' Q2H > 0}- (46) 

n— 1 n—1 

follows immediately from ([45]l. 



Considering the ergodic jamming policy A* used by the illegitimate transmitter in Section IV we can use the 



ergodic theorem to conclude that as N 00, ( 46 1 converges to, 

7^2.0 > ^2,0- (47) 
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